BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Rapid7 · 30m agovBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 54m agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 1h agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 2h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 3h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 3h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 4h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 4h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 4h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 5h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 5h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 5h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 6h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 6h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Rapid7 · 30m agovBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 54m agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 1h agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 2h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 3h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 3h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 4h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 4h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 4h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 5h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 5h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 5h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 6h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 6h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

772 results in Breach

🔴 BreachThe Hacker News·42d ago
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the unusual part: the attackers rewired the victims' own Google Workspace rules to copy any message

🔴 BreachThe Hacker News·46d ago
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no